EDBT 2026 Demo / reviewers in the wild / expert
Xiaokuan Zhang
dblp:158/4724
· DBLP profile ↗
41ranked-venue papers
5as first author
31since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 4 first-author · 20 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Detection-aided enhanced reweighted atomic norm minimization method for target localization in UAV swarms under multipath environments
Fan Lv, Xiaokuan Zhang, Ninghui Li 0003, Weike Feng, Yuan Liu 0007, Guimei Zheng |
Signal Process. | 2 |
| 2026 | Ruby: Unmasking Unsafe Rust in Stripped Binaries via Machine Learning
Sangdon Park 0001, HyungSeok Han, Xiaokuan Zhang, Taesoo Kim |
DSN | 4 |
| 2026 | Target localization method via ANM-ADMM adapted to fluctuant multipath environment without prior knowledge
Fan Lv, Xiaokuan Zhang, Yuan Liu 0007, Ninghui Li 0003 |
Signal Process. | 2 |
| 2025 | An Empirical Study on Cross-chain Transactions: Costs, Inconsistencies, and Activities
Kailun Yan, Pranav Agrawal 0002, Jiasun Li, Wenrui Diao, Xiaokuan Zhang |
AsiaCCS | 6 |
| 2025 | Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareabstractVirtual Reality (VR) technology is rapidly growing in recent years. VR devices such as Meta Quest 3 utilize numerous sensors to collect users' data to provide an immersive experience. Due to the extensive data collection and the immersive nature, the security of VR devices is paramount. Leading VR devices often adopt and customize Android systems, which makes them susceptible to both Android-based vulnerabilities and new issues introduced by VR-specific customizations (e.g., system services to support continuous head and hand tracking). While prior work has extensively examined the security properties of the Android software stack, how these security properties hold for VR systems remains unexplored. In this paper, we present the first comprehensive security analysis of VR firmware. We collect over 300 versions of VR firmware from two major vendors, Quest and Pico, and perform a longitudinal analysis across the kernel layer, the system binary and library layer, and the application layer. We have identified several security issues in these VR firmware, including missing kernel-level security features, insufficient binary hardening, inconsistent permission enforcement, and inadequate SELinux policy enforcement. Based on our findings, we synthesize recommendations for VR vendors to improve security and trust for VR devices. This paper will act as an important security resource for VR developers, users, and vendors, and will also direct future advancements in secure VR ecosystem Vamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan Zhang |
CCS | 4 |
| 2025 | Rug: Turbo Llm for Rust Unit Test GenerationabstractUnit testing improves software quality by evaluating isolated sections of the program. This approach alleviates the need for comprehensive program-wide testing and confines the potential error scope within the software. However, unit test development is time-consuming, requiring developers to create appropriate test contexts and determine input values to cover different code regions. This problem is particularly pronounced in Rust due to its intricate type system, making traditional unit test generation tools ineffective in Rust projects. Recently, large language models (LLMs) have demonstrated their proficiency in understanding programming language and completing software engineering tasks. However, merely prompting LLMs with a basic prompt like “generate unit test for the following source code” often results in code with compilation errors. In addition, LLM-generated unit tests often have limited test coverage. To bridge this gap and harness the capabilities of LLM, we design and implement RUG, an end-to-end solution to automatically generate the unit test for Rust projects. To help LLM's generated test pass Rust strict compilation checks, RUG designs a semantic-aware bottom-up approach to divide the context construction problem into dependent sub-problems. It solves these sub-problems sequentially using an LLM and merges them to a complete context. To increase test coverage, RUG integrates coverage-guided fuzzing with LLM to prepare fuzzing harnesses. Applying RUG on 17 real-world Rust programs (average$24,937 \text{LoC}$), we show that RUG can achieve a high code coverage, up to$\mathbf{7 1. 3 7 \%}$, closely comparable to human effort$(\mathbf{7 3. 1 8 \%})$. We submitted 113 unit tests generated by RUG covering the new code: 53 of them have been accepted, 17 rejected, and 43 are pending for review. Fan Sang, Yizhuo Zhai, Xiaokuan Zhang, Taesoo Kim |
ICSE | 4 |
| 2025 | An Empirical Study of Proxy Contracts at the Ethereum Ecosystem ScaleabstractThe proxy design pattern separates data and code in smart contracts into proxy and logic contracts. Data resides in proxy contracts, while code is sourced from logic contracts. This pattern allows for flexible smart contract development, enabling upgradeability, extensibility, and code reuse. Despite its popularity and importance, there is currently no systematic study to understand the prevalence, use scenarios, and development pitfalls of proxies. We present the first comprehensive study on Ethereum proxies. To gather a dataset of proxies, we introduce PROXYEX, the first framework to detect proxies from bytecode, achieving over 99% accuracy. Using PROXYEX, we collected a dataset of 2,031,422 Ethereum proxies and conducted the first large-scale empirical study. We analyzed proxy numbers and transaction traffic to understand their current status on Ethereum. We identified four proxy use patterns: upgradeability, extensibility, code-sharing, and code-hiding. We also pinpointed three common issues: proxy-logic storage collision, logic-logic storage collision, and uninitialized contracts, creating checkers for these by replaying historical transactions. Our study reveals that upgradeability isn't the sole reason for proxy adoption in DApps, and many proxies present issues like storage collisions and uninitialized contracts, which enhances the understanding of proxies and guide future smart contract research on the development, usage, quality assurance, and bug detection of proxies. Preksha Shukla, Wuqi Zhang, Zhuo Zhang 0002, Pranav Agrawal 0002, Zhiqiang Lin 0001, Xiangyu Zhang 0001, Xiaokuan Zhang |
ICSE | 8 |
| 2025 | Hunting Insecure UI Properties in Extended RealityabstractThis paper addresses critical security vulnerabilities in Extended Reality (XR) user interfaces (UIs) by developing systematic detection mechanisms. Recent research has identified that XR applications are susceptible to UI-based attacks due to insecure properties like spatial overlap and invisible boundaries. These vulnerabilities arise from XR's unique characteristic of integrating digital content into the physical world, where multiple virtual elements from different sources must coexist in the same perceptual space. We present a detection framework that helps developers identify potentially malicious UI elements through continuous runtime analysis. Our framework implements two key detection mechanisms: a same-space detector that identifies overlapping UI elements that could enable clickjacking attacks, and an invisibility detector that discovers hidden boundary objects that could block legitimate interactions. We implement this framework as a Unity plugin and demonstrate its effectiveness through comprehensive evaluation across multiple attack scenarios. Our results show that the framework successfully detects both same-space and invisibility attacks while maintaining acceptable performance overhead. This work represents a significant step toward securing XR applications against UI-based attacks and provides developers with practical tools to identify and mitigate these vulnerabilities during development and runtime. Bertram Liu, Vamsi Shankar Simhadri, Xiaokuan Zhang |
MobiHoc | 3 |
| 2025 | Portal: Fast and Secure Device Access with Arm CCA for Modern Arm Mobile System-on-Chips (SoCs)abstractThe increasing integration of diverse co-processors and peripherals within mobile Arm System-on-Chips (SoCs) presents significant challenges for secure and efficient device I/O. Existing approaches relying on memory encryption introduce substantial performance and power overheads, which are exacerbated by the need for real-time data processing and strict power efficiency requirements in mobile platforms. These issues hinder the wider adoption of Arm Confidential Compute Architecture (CCA), which aims to provide robust security guarantees. To address these challenges, we present Portal, a secure and efficient device I/O interface for Arm CCA on mobile Arm SoCs. Portal achieves secure I/O through strict memory isolation without the need for memory encryption. By leveraging the memory isolation mechanism in Arm CCA, Portal enforces hardware-level access control, ensuring that only designated Realm virtual machines and peripherals can access the Portal-protected plaintext memory regions. This design eliminates the overhead associated with encryption, supports dynamic peripheral integration, and maintains robust security guarantees. The evaluation results demonstrate that Portal incurs a minimal one-time overhead of 9.8%, while enhancing scalability and power efficiency, making it a pivotal solution for fostering the adoption of the upcoming Arm CCA in mobile and resource-constrained environments. Fan Sang, Jaehyuk Lee, Xiaokuan Zhang, Taesoo Kim |
SP | 3 |
| 2025 | TYPEPULSE: Detecting Type Confusion Bugs in Rust Programs
Hung-Mao Chen, Shu Wang 0004, Xiaokuan Zhang, Kun Sun 0001 |
USENIX Security Symposium | 4 |
| 2025 | Deep Unfolded Atomic Norm Minimization Algorithm for Space-Time Adaptive ProcessingabstractAs an effective clutter suppression method for airborne radar, the atomic norm minimization (ANM)-based space-time adaptive processing (STAP) method suffers from high computational complexity and parameter setting difficulty. To solve these problems, a deep unfolded (DU) ANM algorithm is proposed for STAP in this study. First, the clutter estimation problem based on ANM is established. Then, the problem is solved via the alternating direction method of multipliers (ADMMs) and a deep neural network (DNN), which is trained by designing an appropriate loss function and constructing a complete dataset. At last, the clutter-plus-noise covariance matrix (CNCM) and the STAP weighting vector are obtained by processing the training range cell data via the trained network. Simulation results show that the proposed DU-ANM-STAP method can achieve higher clutter and noise suppression performance with lower computational cost than the existing ANM-STAP methods. Xiaokuan Zhang, Weike Feng, Xixi Chen, Ninghui Li 0003 |
IEEE Geosci. Remote. Sens. Lett. | 2 |
| 2024 | Breaking the Privacy Barrier: On the Feasibility of Reorganization Attacks on Ethereum Private TransactionsabstractIn Ethereum, private transactions are designed to circumvent the public network, but they can sometimes be leaked into the public network before on-chain posting. Motivated by the huge profits of these private transactions, we propose reorganization attacks in the current Proof-of-Stake (PoS) consensus mechanism, enabling malicious validators to actively leak private transactions for profits. While prior research on reorganization attacks has focused on consensus security, our work is the first study shedding light on the economic implications of exploiting private transactions. Through theoretical analysis and extensive simulations, we confirm the effectiveness of our attacks. Additionally, we comprehensively examine real-world datasets covering 30,062,232 private transactions from September 15, 2022 to Decemeber 31, 2023 for profit analysis, uncovering that the most lucrative private transactions are often tied to Maximum Extractable Value (MEV). To further bolster the practicability and feasibility of our attacks, we scrutinize real-world cases aligning with our attack patterns. We find that attacks are risk-free due to the predictability of validators’ duties. Our findings offer valuable insights into the economics of exploiting private transactions, potential vulnerabilities, and consensus security, laying the foundation for future research. Xingyu Lyu, Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang, Zhiqiang Lin 0001 |
ACSAC | 4 |
| 2024 | Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationabstractAs the field of Web3 continues its rapid expansion, the security of Web3 authentication, often the gateway to various Web3 applications, becomes increasingly crucial. Despite its widespread use as a login method by numerous Web3 applications, the security risks of Web3 authentication have not received much attention. This paper investigates the vulnerabilities in the Web3 authentication process and proposes a new type of attack, dubbed blind message attacks. In blind message attacks, attackers trick users into blindly signing messages from target applications by exploiting users' inability to verify the source of messages, thereby achieving unauthorized access to the target application. We have developed Web3AuthChecker, a dynamic detection tool that interacts with Web3 authentication-related APIs to identify vulnerabilities. Our evaluation of real-world Web3 applications shows that a staggering 75.8% (22/29) of Web3 authentication deployments are at risk of blind message attacks. In response to this alarming situation, we implemented Web3AuthGuard on the open-source wallet MetaMask to alert users of potential attacks. Our evaluation results show that Web3AuthGuard can successfully raise alerts in 80% of the tested Web3 authentications. We have responsibly reported our findings to vulnerable websites and have been assigned two CVE IDs. Kailun Yan, Xiaokuan Zhang, Wenrui Diao |
CCS | 2 |
| 2024 | VPVet: Vetting Privacy Policies of Virtual Reality AppsabstractVirtual reality (VR) apps can harvest a wider range of user data than web/mobile apps running on personal computers or smartphones. Existing law and privacy regulations emphasize that VR developers should inform users of what data are collected/used/shared (CUS) through privacy policies. However, privacy policies in the VR ecosystem are still in their early stages, and many developers fail to write appropriate privacy policies that comply with regulations and meet user expectations. In this paper, we propose VPVet to automatically vet privacy policy compliance issues for VR apps. VPVet first analyzes the availability and completeness of a VR privacy policy and then refines its analysis based on three key criteria: granularity, minimization, and consistency of CUS statements. Our study establishes the first and currently largest VR privacy policy dataset named VRPP, consisting of privacy policies of 11,923 different VR apps from 10 mainstream platforms. Our vetting results reveal severe privacy issues within the VR ecosystem, including the limited availability and poor quality of privacy policies, along with their coarse granularity, lack of adaptation to VR traits and the inconsistency between CUS statements in privacy policies and their actual behaviors. We open-source VPVet system along with our findings at repository https://github.com/kalamoo/PPAudit, aiming to raise awareness within the VR community and pave the way for further research in this field. Yuxia Zhan, Yan Meng 0001, Yichang Xiong, Xiaokuan Zhang, Lichuan Ma, Guoxing Chen, Qingqi Pei, Haojin Zhu |
CCS | 5 |
| 2024 | Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security ImplicationsabstractIn recent years, the growth of mobile advertising has been driven by in-app programmatic advertising and technologies like Real-Time Bidding (RTB). However, this growth has also led to an increase in ad fraud, such as click injection, background ad activity, etc. While existing studies have primarily concentrated on ad fraud within individual apps or devices, this paper introduces a new form of collusion-based ad fraud, named ad attribution laundering fraud (ALF). ALF involves multiple apps collaborating to deceive advertisers by misrepresenting the app where ads are displayed. The collusion-based approach allows lower-quality apps to exploit the reputable identities of seemingly legitimate apps. This deceives advertisers or ad networks into believing that the advertisements they place are reaching potentially valid end-users on the legitimate app. The seemingly legitimate ad events and ad attribution procedures employed by individual apps in such attacks can evade detection by existing tools. Chaofan Shou, Guoxing Chen, Xiaokuan Zhang, Yan Meng 0001, Shuang Hao 0001, Haojin Zhu |
CCS | 5 |
| 2024 | Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android AppsabstractRecently, clipboard usage has become prevalent in mobile apps allowing users to copy and paste text within the same app or across different apps. However, insufficient access control on the clipboard in the mobile operating systems exposes its contained data to high risks where one app can read the data copied in other apps and store it locally or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile app ecosystem. To establish the missing links, this paper proposes an automated tool, ClipboardScope, that leverages the principled static program analysis to uncover the clipboard data usage in mobile apps at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an app. ClipboardScope is evaluated on 26,201 out of a total of 2.2 million mobile apps available on Google Play as of June 2022 that access and process the clipboard text. It identifies 23,948, 848, 1,075, and 330 apps that are recognized as the four designated categories, respectively. In addition, we uncovered a prevalent programming habit of using the SharedPreferences object to store historical data, which can become an unnoticeable privacy leakage channel. Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang, Lei Xue 0001, Xiapu Luo, Qingchuan Zhao |
ICSE | 4 |
| 2024 | SENSE: Enhancing Microarchitectural Awareness for TEEs via Subscription-Based Notification
Fan Sang, Jaehyuk Lee, Xiaokuan Zhang, Scott Constable, Yuan Xiao 0001, Michael Steiner 0001, Mona Vij, Taesoo Kim |
NDSS | 3 |
| 2024 | Security of Cross-chain Bridges: Attack Surfaces, Defenses, and Open ProblemsabstractCross-chain bridges play a pivotal role in enabling token and data exchanges between disparate blockchains. Despite their growing popularity, these bridges are still in their infancy and have been the target of numerous attacks, leading to significant financial losses. Current literature lacks a comprehensive examination of the security landscape surrounding cross-chain bridges, with existing incident reports dispersed and unconsolidated. Addressing this gap, this paper presents a systematic investigation into the security challenges facing cross-chain bridges. We begin by outlining the key features of current cross-chain bridges, including their applications, verification processes, communication models, and a novel threefold categorization. From this foundation, we identify 12 potential attack vectors and develop a taxonomy of cross-chain bridge attacks observed over the past three years, classifying them into 10 unique categories. Each category is detailed with corresponding vulnerabilities, illustrated through Solidity code examples. Furthermore, we explore existing defense mechanisms, propose potential security solutions, and highlight crucial open questions and avenues for future research. This paper aims to illuminate the path towards more secure cross-chain bridge designs and stimulate further investigation into fortifying the cross-chain bridge ecosystem. Xiaokuan Zhang, Yinqian Zhang, Zhiqiang Lin 0001 |
RAID | 2 |
| 2024 | Penetration Vision through Virtual Reality Headsets: Identifying 360-degree Videos from Head Movements
Anh Nguyen 0011, Xiaokuan Zhang, Zhisheng Yan |
USENIX Security Symposium | 2 |
| 2024 | An off-grid direction-of-arrival estimator based on sparse Bayesian learning with three-stage hierarchical Laplace priorsabstractFor direction-of-arrival (DOA) estimation problems, sparse Bayesian learning (SBL) has achieved excellent estimation performance, especially in sparse arrays. However, numerous SBL-based methods with hyperparameters assigned to Gaussian priors cannot enhance sparsity well, and mainly focus on the nested array (NA) or the co-prime array (CPA) that cause relatively large degree of freedom (DOF) losses. Based on this, we propose a novel method with a Bayesian framework containing three-stage hierarchical Laplace priors that significantly promote sparsity. Moreover, the proposed method is based on the minimum hole array (MHA) that retains a larger array aperture than NA or CPA after redundancy removal, which is required and achieved simultaneously by a denoising operation. In addition, to correct the intractable off-grid model errors caused by grid mismatch, a new refinement operation is developed. And, the refinement empirically outperforms others based on Taylor expansion. Extensive simulations are presented to confirm the superiority of the proposed method beyond state-of-the-art methods. Ninghui Li 0003, Xiaokuan Zhang, Fan Lv |
Signal Process. | 2 |
| 2024 | Ensuring State Continuity for Confidential Computing: A Blockchain-Based ApproachabstractPublic cloud platforms have employed Trusted Execution Environment (TEE) technology to provide confidential computing services. However, applications running on cloud TEEs are susceptible to rollback or forking attacks. Their states can be rolled back to an outdated version or split into multiple conflicting versions, violating state continuity. Existing solutions against these attacks either rely on centralized trust assumption (e.g., trusted server) or have limited performance (e.g., tens of state updates per second). In this paper, we introduce Narrator-Pro (an upgrade to the original Narrator), a secure and practical distributed system that utilizes blockchain technology and TEEs to provide high-performance state continuity protection for TEE applications in the cloud. Specifically, we use the blockchain to initialize the system, which lays down the decentralized trust base with minimal interaction overhead. Meanwhile, we leverage the distributed system composed of TEEs to provide fast and unlimited state updates. We have implemented a proof-of-concept of Narrator-Pro in Intel SGX and conducted extensive evaluations in both the WAN and the LAN. Our results show that in a LAN environment with 5 nodes, Narrator-Pro can support around 8k state updates per second with a latency of 3.58ms. This performance is 30x higher than ROTE and 70× higher than using a TPM counter. Xiang Li 0166, Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | VeriTrain: Validating MLaaS Training Efforts via Anomaly DetectionabstractMachine learning as a service (MLaaS) offers users the benefit of training state-of-the-art neural network models on fast hardware with low costs. However, it also brings security concerns since the user does not fully trust the cloud. To prove to the user that the ML training results are legitimate, existing approaches mainly adopt cryptographic techniques such as secure multi-party computation, which incur large overheads. In this paper, we model the problem of verifying ML training efforts as an anomaly detection problem. We design a verification system, dubbedVeriTrain, which combines unsupervised anomaly detection approaches and hypothesis testing techniques to verify the legitimacy of training efforts on the MLaaS cloud.VeriTrainis run inside trusted execution environments (TEEs) on the same cloud machine to ensure the integrity of its execution. We consider a threat model where the cloud model trainer is a lazy attacker and tries to foolVeriTrainwith minimum training effort. We perform extensive evaluations on multiple neural network models and datasets, which shows thatVeriTrainperforms well in detecting parameter updates crafted by the attacker. We also implementVeriTrainwith Intel SGX and show that it only incurs moderate overheads. Xiaokuan Zhang, Yang Zhang 0016, Yinqian Zhang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Veil: A Protected Services Framework for Confidential Virtual MachinesabstractConfidential virtual machines (CVMs) enabled by AMD SEV provide a protected environment for sensitive computations on an untrusted cloud. Unfortunately, CVMs are typically deployed with huge and vulnerable operating system kernels, exposing the CVMs to attacks that exploit kernel vulnerabilities. Veil is a versatile CVM framework that efficiently protects critical system services like shielding sensitive programs, which cannot be entrusted to the buggy kernel. Veil leverages a new hardware primitive, virtual machine privilege levels (VMPL), to install a privileged security monitor inside the CVM. We overcome several challenges in designing Veil, including (a) creating unlimited secure domains with a limited number of VMPLs, (b) establishing resource-efficient domain switches, and (c) maintaining commodity kernel backwards-compatibility with only minor changes. Our evaluation shows that Veil incurs no discernible performance slowdown during normal CVM execution while incurring a modest overhead (2 -- 64%) when running its protected services across real-world use cases. Adil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang, Pedro Fonseca 0001 |
ASPLOS (4) | 4 |
| 2023 | Recovering Fingerprints from In-Display Fingerprint Sensors via Electromagnetic Side ChannelabstractRecently, in-display fingerprint sensors have been widely adopted in newly-released smartphones. However, we find this new technique can leak information about the user's fingerprints during a screen-unlocking process via the electromagnetic (EM) side channel that can be exploited for fingerprint recovery. We propose FPLogger to demonstrate the feasibility of this novel side-channel attack. Specifically, it leverages the emitted EM emanations when the user presses the in-display fingerprint sensor to extract fingerprint information, then maps the captured EM signals to fingerprint images and develops 3D fingerprint pieces to spoof and unlock the smartphones. We have extensively evaluated the effectiveness of FPlogger on five commodity smartphones equipped with both optical and ultrasonic in-display fingerprint sensors, and the results show it achieves promising similarities in recovering fingerprint images. In addition, results from 50 end-to-end spoofing attacks also present FPLogger achieves 24% (top-1) and 54% (top-3) success rates in spoofing five different smartphones. Tao Ni 0003, Xiaokuan Zhang, Qingchuan Zhao |
CCS | 2 |
| 2023 | Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot LearningabstractRecently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning. Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
MobiCom | 3 |
| 2023 | Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side ChannelsabstractToday, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors. Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao |
SP | 2 |
| 2023 | POLICYCOMP: Counterpart Comparison of Privacy Policies Uncovers Overbroad Personal Data Collection Practices
Chengyongxiao Wei, Guoxing Chen, Xiaokuan Zhang, Suguo Du, Haojin Zhu |
USENIX Security Symposium | 5 |
| 2022 | NARRATOR: Secure and Practical State Continuity for Trusted Execution in the CloudabstractPublic cloud platforms have leveraged Trusted Execution Environment (TEE) technology to provide confidential computing services. However, TEE-protected applications still suffer from rollback or forking attacks, in which their states could be rolled back to a stale version or be forked into multiple versions, resulting in state continuity violations. Existing solutions against these attacks either rely on weak threat models based on centralized trust (e.g., trusted server) or suffer from large performance overheads (e.g., tens of state updates per second). In this paper, we propose Narrator, a secure and practical system, (1) that relies on a blockchain (i.e., decentralized trust) and TEEs, and (2) that provides high-performance state continuity protection like unlimited and fast state updates for applications in cloud TEEs. The intuition behind our design is simple. Our design uses the blockchain to initialize a distributed system of TEEs, laying down the decentralized trust base with a small interaction overhead, while the distributed system provides performant state continuity protection. Our distributed system adopts a customized version of the consistent broadcast protocol and leverages advanced techniques to make state updates processed with one round trip delay on average. We build a proof-of-concept of Narrator on Intel SGX (i.e., a representative design of TEEs) and do extensive experiments to evaluate its performance. Our evaluation results show that in a LAN environment with 5 nodes, Narrator can support about 6k state updates per second, meanwhile keeping the latency as low as 3-8 ms. The throughput is 30x larger than that in ROTE and 70x larger than using a TPM counter. Jianyu Niu, Xiaokuan Zhang, Yinqian Zhang |
CCS | 3 |
| 2022 | PRIDWEN: Universally Hardening SGX Programs via Load-Time Synthesis
Fan Sang, Ming-Wei Shih, Sangho Lee 0001, Xiaokuan Zhang, Michael Steiner 0001, Mona Vij, Taesoo Kim |
USENIX ATC | 4 |
| 2021 | Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficabstractAlong with gaining popularity of Real-Time Bidding (RTB) based programmatic advertising, the click farm based invalid traffic, which leverages massive real smartphones to carry out large-scale ad fraud campaigns, is becoming one of the major threats against online advertisement. In this study, we take an initial step towards the detection and large-scale measurement of the click farm based invalid traffic. Our study begins with a measurement on the device's features using a real-world labeled dataset, which reveals a series of features distinguishing the fraudulent devices from the benign ones. Based on these features, we develop EvilHunter, a system for detecting fraudulent devices through ad bid request logs with a focus on clustering fraudulent devices. EvilHunter functions by 1) building a classifier to distinguish fraudulent and benign devices; 2) clustering devices based on app usage patterns; and 3) relabeling devices in clusters through majority voting. EvilHunter demonstrates 97% precision and 95% recall on a real-world labeled dataset. By investigating a super click farm, we reveal several cheating strategies that are commonly adopted by fraudulent clusters. We further reduce the overhead of EvilHunter and discuss how to deploy the optimized EvilHunter in a real-world system. We are in partnership with a leading ad verification company to integrate EvilHunter into their industrial platform. Suibin Sun, Le Yu 0002, Xiaokuan Zhang, Minhui Xue 0001, Ren Zhou, Haojin Zhu, Shuang Hao 0001, Xiaodong Lin 0001 |
CCS | 3 |
| 2021 | Dissecting Click Fraud Autonomy in the WildabstractAlthough the use of pay-per-click mechanisms stimulates the prosperity of the mobile advertisement network, fraudulent ad clicks result in huge financial losses for advertisers. Extensive studies identify click fraud according to click/traffic patterns based on dynamic analysis. However, in this study, we identify a novel click fraud, named humanoid attack, which can circumvent existing detection schemes by generating fraudulent clicks with similar patterns to normal clicks. We implement the first tool ClickScanner to detect humanoid attacks on Android apps based on static analysis and variational AutoEncoders (VAEs) with limited knowledge of fraudulent examples. We define novel features to characterize the patterns of humanoid attacks in the apps' bytecode level. ClickScanner builds a data dependency graph (DDG) based on static analysis to extract these key features and form a feature vector. We then propose a classification model only trained on benign datasets to overcome the limited knowledge of humanoid attacks. Yan Meng 0001, Haotian Hu, Xiaokuan Zhang, Minhui Xue 0001, Haojin Zhu |
CCS | 4 |
| 2020 | SurfaceFleet: Exploring Distributed Interactions Unbounded from Device, Application, User, and TimeabstractKnowledge work increasingly spans multiple computing surfaces. Yet in status quo user experiences, content as well as tools, behaviors, and workflows are largely bound to the current device-running the current application, for the current user, and at the current moment in time. SurfaceFleet is a system and toolkit that uses resilient distributed programming techniques to explore cross-device interactions that are unbounded in these four dimensions of device, application, user, and time. As a reference implementation, we describe an interface built using SurfaceFleet that employs lightweight, semi-transparent UI elements known as Applets. Applets appear always-on-top of the operating system, application windows, and (conceptually) above the device itself. But all connections and synchronized data are virtualized and made resilient through the cloud. For example, a sharing Applet known as a Portfolio allows a user to drag and drop unbound Interaction Promises into a document. Such promises can then be fulfilled with content asynchronously, at a later time (or multiple times), from another device, and by the same or a different user. Frederik Brudy, David Ledo, Michel Pahud, Nathalie Henry Riche, Christian Holz 0001, Anand Waghmare, Hemant Bhaskar Surale, Marcus Peinado, Xiaokuan Zhang, Shannon Joyner, Badrish Chandramouli, Umar Farooq Minhas, Jonathan Goldstein, William Buxton, Ken Hinckley |
UIST | 9 |
| 2020 | TXSPECTOR: Uncovering Attacks in Ethereum from Transactions
Xiaokuan Zhang, Yinqian Zhang, Zhiqiang Lin 0001 |
USENIX Security Symposium | 2 |
| 2019 | Statistical Privacy for Streaming Traffic
Xiaokuan Zhang, Jihun Hamm, Michael K. Reiter, Yinqian Zhang |
NDSS | 1 |
| 2018 | A Measurement Study of Authentication Rate-Limiting Mechanisms of Modern WebsitesabstractText passwords remain a primary means for user authentication on modern computer systems. However, recent studies have shown the promises of guessing user passwords efficiently with auxiliary information of the targeted accounts, such as the users' personal information, previously used passwords, or those used in other systems. Authentication rate-limiting mechanisms, such as account lockout and login throttling, are common methods to defeat online password cracking attacks. But to date, no published studies have investigated how authentication rate-limiting is implemented by popular websites. In this paper, we present a measurement study of such countermeasures against online password cracking. Towards this end, we propose a black-box approach to modeling and validating the websites' implementation of the rate-limiting mechanisms. We applied the tool to examine all 182 websites that we were able to analyze in the Alexa Top 500 websites in the United States. The results are rather surprising: 131 websites (72%) allow frequent, unsuccessful login attempts without account lockout or login throttling (though some of these websites force the adversary to lower the login frequency or constantly change his IP addresses to circumvent the rate-limiting enforcement). The remaining 51 websites are not absolutely secure either: 28 websites may block a legitimate user with correct passwords when the account is locked out, effectively enabling authentication denial-of-service attacks. Xiaokuan Zhang, Ziman Ling, Yinqian Zhang, Zhiqiang Lin 0001 |
ACSAC | 2 |
| 2018 | HoMonit: Monitoring Smart Home Apps from Encrypted TrafficabstractSmart home is an emerging technology for intelligently connecting a large variety of smart sensors and devices to facilitate automation of home appliances, lighting, heating and cooling systems, and security and safety systems. Our research revolves around Samsung SmartThings, a smart home platform with the largest number of apps among currently available smart home platforms. The previous research has revealed several security flaws in the design of SmartThings, which allow malicious smart home apps (or SmartApps) to possess more privileges than they were designed and to eavesdrop or spoof events in the SmartThings platform. To address these problems, this paper leverages side-channel inference capabilities to design and develop a system, dubbed HoMonit, to monitor SmartApps from encrypted wireless traffic. To detect anomaly, HoMonit compares the SmartApps activities inferred from the encrypted traffic with their expected behaviors dictated in their source code or UI interfaces. To evaluate the effectiveness of HoMonit, we analyzed 181 official SmartApps and performed evaluation on 60 malicious SmartApps, which either performed over-privileged accesses to smart devices or conducted event-spoofing attacks. The evaluation results suggest that HoMonit can effectively validate the working logic of SmartApps and achieve a high accuracy in the detection of SmartApp misbehaviors. Wei Zhang 0001, Yan Meng 0001, Yugeng Liu, Xiaokuan Zhang, Yinqian Zhang, Haojin Zhu |
CCS | 4 |
| 2018 | OS-level Side Channels without Procfs: Exploring Cross-App Information Leakage on iOS
Xiaokuan Zhang, Xueqiang Wang, Xiaolong Bai, Yinqian Zhang, XiaoFeng Wang 0001 |
NDSS | 1 |
| 2017 | Detecting Privileged Side-Channel Attacks in Shielded Execution with Déjà VuabstractIntel Software Guard Extension (SGX) protects the confidentiality and integrity of an unprivileged program running inside a secure enclave from a privileged attacker who has full control of the entire operating system (OS). Program execution inside this enclave is therefore referred to as shielded. Unfortunately, shielded execution does not protect programs from side-channel attacks by a privileged attacker. For instance, it has been shown that by changing page table entries of memory pages used by shielded execution, a malicious OS kernel could observe memory page accesses from the execution and hence infer a wide range of sensitive information about it. In fact, this page-fault side channel is only an instance of a category of side-channel attacks, here called privileged side-channel attacks, in which privileged attackers frequently preempt the shielded execution to obtain fine-grained side-channel observations. In this paper, we present Deja Vu, a software framework that enables a shielded execution to detect such privileged side-channel attacks. Specifically, we build into shielded execution the ability to check program execution time at the granularity of paths in its control-flow graph. To provide a trustworthy source of time measurement, Deja Vu implements a novel software reference clock that is protected by Intel Transactional Synchronization Extensions (TSX), a hardware implementation of transactional memory. Evaluations show that Deja Vu effectively detects side-channel attacks against shielded execution and against the reference clock itself. Sanchuan Chen, Xiaokuan Zhang, Michael K. Reiter, Yinqian Zhang |
AsiaCCS | 2 |
| 2016 | Return-Oriented Flush-Reload Side Channels on ARM and Their Implications for Android DevicesabstractCache side-channel attacks have been extensively studied on x86 architectures, but much less so on ARM processors. The technical challenges to conduct side-channel attacks on ARM, presumably, stem from the poorly documented ARM cache implementations, such as cache coherence protocols and cache flush operations, and also the lack of understanding of how different cache implementations will affect side-channel attacks. This paper presents a systematic exploration of vectors for flush-reload attacks on ARM processors. flush-reload attacks are among the most well-known cache side-channel attacks on x86. It has been shown in previous work that they are capable of exfiltrating sensitive information with high fidelity. We demonstrate in this work a novel construction of flush-reload side channels on last-level caches of ARM processors, which, particularly, exploits return-oriented programming techniques to reload instructions. We also demonstrate several attacks on Android OS (e.g., detecting hardware events and tracing software execution paths) to highlight the implications of such attacks for Android devices. Xiaokuan Zhang, Yuan Xiao 0001, Yinqian Zhang |
CCS | 1 |
| 2016 | One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege Escalation
Yuan Xiao 0001, Xiaokuan Zhang, Yinqian Zhang, Radu Teodorescu |
USENIX Security Symposium | 2 |
| 2014 | You are where you have been: Sybil detection via geo-location analysis in OSNsabstractOnline Social Networks (OSNs) are facing an increasing threat of sybil attacks. Sybil detection is regarded as one of major challenges for OSN security. The existing sybil detection proposals that leverage graph theory or exploit the unique clickstream patterns are either based on unrealistic assumptions or limited to the service providers. In this study, we introduce a novel sybil detection approach by exploiting the fundamental mobility patterns that separate real users from sybil ones. The proposed approach is motivated as follows. On the one hand, OSNs including Yelp and Dianping allow us to obtain the users' mobility trajectories based on their online reviews and the locations of their visited shops/restaurants. On the other side, a real user's mobility is generally predictable and confined to a limited neighborhood while the sybils' mobility is forged based on the paid review missions. To exploit the mobility differences between the real and sybil users, we introduce an entropy based definition to capture users' mobility patterns. Then we design a new sybil detection model by incorporating the newly defined location entropy based metrics into other traditional feature sets. The proposed sybil detection model can significantly improve the performance of sybil detections, which is well demonstrated by extensive evaluations based on the data set from Dianping. Xiaokuan Zhang, Haizhong Zheng, Suguo Du, Haojin Zhu |
GLOBECOM | 1 |